Case management systems
Workstation and network configuration, access control and backup around case management platforms used to track client services and outcomes. Application bugs escalate to the vendor.
Social Services & Nonprofit IT · Vancouver, BC
A Vancouver social services or nonprofit organization usually runs on a tighter IT budget than a comparably sized business while holding some of the most sensitive personal information a small organization can handle: client case files that can include health, housing and income detail, and a donor database that funders and the public expect to be handled responsibly. A case management system with weak access control, a donor database with no backup, or a grant funder's data security requirement that nobody has actually verified can each create real exposure for the people an organization serves. Hexafusion supports Lower Mainland social services and nonprofit organizations with practical, budget-aware IT that still meets the standard this sensitive work requires.
Workstation and network configuration, access control and backup around case management platforms used to track client services and outcomes. Application bugs escalate to the vendor.
Licensing, backup and access control for donor management platforms such as those built on common nonprofit CRM tools, kept secure and properly backed up.
Infrastructure support for the systems your organization uses to track and report on grant-funded program outcomes.
Access-controlled systems for client intake and referral information, especially where multiple staff or partner organizations need shared but controlled access.
Licensing and access control for volunteer scheduling and management tools.
Network and remote access support for organizations operating across multiple program sites or with staff working in the community.
BC PIPA governs how a nonprofit organization collects, uses and discloses personal information generally, and the BC Freedom of Information and Protection of Privacy Act (FOIPPA) can apply instead of PIPA for organizations that are funded or operated in a way that brings them under public body rules, which is worth confirming for your specific organization. PIPEDA applies alongside provincial law for activities in the course of commercial activity. Client case files frequently include health, housing or income information that deserves particularly careful access control, and many funders attach their own data security requirements as a condition of grant funding that go beyond general privacy law. This is general information, not legal advice.
We start with an AI readiness assessment that looks at where program and administrative staff could use AI tools without exposing client case data, sized to a realistic nonprofit budget. We set up Copilot and other approved AI tools securely inside your Microsoft 365 tenant, configure data protection so client and donor information cannot leak into a public AI model, and train staff on safe use. For organizations that want to go further, we build custom assistants, including our own AI phone assistant for intake and general inquiry call handling. Any AI build-out beyond basic setup and training is scoped and quoted as its own separate project.
Many social services and nonprofit organizations start on Foundation given budget constraints, with help desk billed by the hour as needed. Organizations that want day-to-day IT fully handled, which is most that carry an active caseload, typically move to Managed, our generally recommended plan, which includes unlimited remote help desk during business hours (subject to our Fair Use Policy) and onboarding and offboarding support for staff and program turnover. Organizations under funder data security requirements, or handling particularly sensitive case data, often move to Secure, which adds onsite support. Onsite support is included only on our Secure and Enterprise plans; remote-only plans do not include a site visit. After-hours response, a quarterly vCIO review and ongoing testing are Enterprise-only. Servers, including any on-premises server or always-on cloud server you want us to manage, are an add-on and are not included in any plan. See plans for full details.
Do you offer pricing that fits a nonprofit budget?
We work within standard plan pricing and help you choose the plan that matches your budget and actual risk, rather than assuming every organization needs the same level of coverage.
Can you help us meet a funder's data security requirement?
Yes. We review what a specific funder requires and help confirm your systems meet it, or close the gap where they do not.
Do you support donor databases and fundraising platforms?
Yes. We handle licensing, backup and access control for the donor management platform your organization uses.
What privacy rules apply to our client case files?
BC PIPA generally applies, though BC FOIPPA can apply instead depending on your organization's funding and structure, alongside PIPEDA for activities in the course of commercial activity. This is general information, not legal advice.
Can you support staff working across multiple program sites?
Yes. We configure secure remote access and multi-site networking so staff can reliably reach client systems from wherever they actually work.
We have no dedicated IT person and a limited budget. Is that a problem?
That is who we are built for. Most organizations this size have no dedicated IT role, and we aim to provide that function at a scale that fits a nonprofit budget.
Reviewed by Alex Barari, Founder, former PCI DSS Internal Security Assessor (ISA).
See pricing built around your staff size and program footprint in a few minutes.
Get your instant quote Contact usAlongside social services and nonprofit organizations, see nonprofit IT support. See the full list on industries we serve.
Social services and nonprofit organization IT support is delivered against a documented baseline aligned to the Canadian Centre for Cyber Security baseline controls and current cyber-insurance underwriting expectations.
Hexafusion is led by founder Alex Barari, a former PCI DSS Internal Security Assessor with 15+ years in enterprise IT and cybersecurity. Every engagement is supported by the same Vancouver-based team that designs the security baseline, reviews the alerts, and shows up on-site when remote troubleshooting reaches its limit.
